CBA Regulatory Compliance Audits 3 โ Questions and Answers
Question 1: During a compliance audit of a bank's anti-money laundering (AML) program, the auditor finds that Customer Due Diligence (CDD) procedures do not include beneficial ownership collection for legal entity customers. Which FinCEN rule is the bank violating?
- FinCEN's Customer Identification Program (CIP) Rule
- FinCEN's Beneficial Ownership Rule (31 CFR 1010.230) (Correct answer)
- FinCEN's Suspicious Activity Report (SAR) Rule
- FinCEN's Currency Transaction Report (CTR) Aggregation Rule
Correct answer: FinCEN's Beneficial Ownership Rule (31 CFR 1010.230)
FinCEN's Beneficial Ownership Rule requires covered financial institutions to collect information on natural persons owning 25% or more of legal entity customers.
Question 2: Under the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule, what is a bank's primary obligation regarding its information security program?
- Encrypt all customer data at rest using AES-256 exclusively
- Develop, implement, and maintain a comprehensive written information security program (Correct answer)
- Conduct annual penetration testing on all public-facing systems
- File quarterly security attestations with the FDIC
Correct answer: Develop, implement, and maintain a comprehensive written information security program
The GLBA Safeguards Rule requires financial institutions to implement a written information security program with administrative, technical, and physical safeguards.
Question 3: A compliance auditor reviewing Regulation CC (Availability of Funds) finds that a bank places a 7-business-day hold on all local checks. What is the likely violation?
- Local checks are exempt from Regulation CC hold requirements
- Regulation CC requires local checks to be made available no later than the second business day after deposit (Correct answer)
- A 7-day hold is permissible for checks over $5,000 regardless of check type
- The hold period is compliant if the customer signed a funds availability disclosure
Correct answer: Regulation CC requires local checks to be made available no later than the second business day after deposit
Regulation CC generally requires local checks to be available by the second business day following deposit, making a blanket 7-day hold a violation.
Question 4: Which of the following would be considered a 'red flag' under the FTC's Red Flags Rule when auditing an identity theft prevention program at a bank?
- A customer updating their address at account opening
- A notice from a credit agency of a fraud alert on a customer's file (Correct answer)
- A customer requesting a stop payment on a check
- A deposit of a government-issued check
Correct answer: A notice from a credit agency of a fraud alert on a customer's file
A fraud alert notice from a credit reporting agency is explicitly listed in the Red Flags Rule as a pattern, practice, or activity indicating possible identity theft.
Question 5: When auditing a bank's compliance with the Military Lending Act (MLA), which interest rate cap applies to covered consumer credit products offered to active-duty servicemembers?
- 18% APR
- 21% APR
- 28% APR
- 36% Military Annual Percentage Rate (MAPR) (Correct answer)
Correct answer: 36% Military Annual Percentage Rate (MAPR)
The MLA caps the Military Annual Percentage Rate (MAPR) at 36% for covered consumer credit products offered to active-duty servicemembers and their dependents.
Question 6: A bank auditor testing Regulation B (Equal Credit Opportunity Act) finds loan officers are requesting applicants' race and national origin on non-HMDA-reportable applications. What is the correct finding?
- No violation because race data is always permitted for compliance monitoring
- A violation because Regulation B prohibits collecting race/national origin data on non-HMDA applications (Correct answer)
- A violation only if the data is used in the credit decision
- Permissible practice if the bank has a written diversity policy
Correct answer: A violation because Regulation B prohibits collecting race/national origin data on non-HMDA applications
Regulation B generally prohibits creditors from requesting race, color, religion, national origin, or sex on applications not subject to HMDA government monitoring requirements.
Question 7: Under the Bank Secrecy Act, which of the following scenarios requires a bank to file a Suspicious Activity Report (SAR)?
- A $9,000 cash deposit made by a long-standing retail customer
- A $6,000 wire transfer to a known correspondent bank in Canada
- A series of transactions totaling $15,000 that appear structured to evade CTR reporting (Correct answer)
- A customer who declines to provide income documentation for a mortgage application
Correct answer: A series of transactions totaling $15,000 that appear structured to evade CTR reporting
Structuring transactions to avoid the CTR threshold is itself a federal crime (31 U.S.C. ยง 5324) and always requires SAR filing regardless of the dollar amounts.
During a compliance audit of a bank's anti-money laundering (AML) program, the auditor finds that Customer Due Diligence (CDD) procedures do not include beneficial ownership collection for legal entity customers.
Which FinCEN rule is the bank violating?